Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

234 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.4)0.69%—RenovateAIHelmAI19/8/20261/10/2026
Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate registryAliases keys with unquoted shell metacharacters to inject commands executed…
AnalizadaAlta (7)0.13%—IBM Powervm Novalink17/7/202611/8/2026
IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations under non-default conditions.
AnalizadaAlta (7.5)0.55%—IBM Powervm Novalink17/7/202611/8/2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
AplazadaCrítica (9.8)0.56%—Novalnet Payment GatewayAI2/7/20262/7/2026
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
AnalizadaAlta (8.5)0.46%—Openstack Nova16/6/202626/6/2026
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.
AplazadaMedia (6.5)0.34%—Nova-toggleAI8/5/202617/6/2026
nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-toggle/toggle/{resource}/{resourceId}) was protected only by web + auth:<guard> middleware. Any user authenticated on the configured guard could call the endpoint and flip boolean attributes on any…
Pendiente de análisisMedia (5.3)0.52%—Cpanel Nova PluginAI8/5/202617/6/2026
A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled legacy Nova path under their home…
AplazadaMedia (5.3)0.46%—NovagalleryAI8/5/202617/6/2026
novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery. This allows unauthenticated users to read image files outside the intended gallery root directory. This issue has been patched in version 2.1.1.
AplazadaAlta (8.2)0.38%—Openstack NovaAIQemu-imgAI18/2/202611/9/2026
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize…
AplazadaMedia (4.6)0.21%—GE Vernova EnervistaAI10/2/202617/6/2026
Vulnerability in GE Vernova Enervista UR Setup on Windows.This issue affects Enervista: 8.6 and previous versions.
AplazadaBaja (2.9)0.24%—GE Vernova Enervista UR SetupAI10/2/202617/6/2026
A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 and prior versions.
AplazadaAlta (8.2)0.33%—Codriapp Innovation AND Software Technologies INC HeygarsonAI30/1/20267/8/2026
Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technologies Inc. HeyGarson allows Fuzzing for application mapping. This issue affects HeyGarson: through 30012026. NOTE: The vendor was contacted and it was learned that the product is not supported.
AnalizadaMedia (6.9)0.16%—Nova-a Planmanager29/1/202617/6/2026
Stored Cross-Site Scripting (XSS) in RLE NOVA's PlanManager. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting malicious payload through the ‘comment’ and ‘brand’ parameters in ‘/index.php’. The payload is stored by the application and subsequently displayed without…
AplazadaAlta (8.7)0.37%—Laravel NovaAI27/1/202617/6/2026
Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application by manipulating the 'range' parameter. Attackers can send simultaneous requests with an extremely high range value to overwhelm and crash the server.
AplazadaMedia (6.5)0.19%—Pixelgrade Nova BlocksAI23/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Nova Blocks nova-blocks allows DOM-Based XSS.This issue affects Nova Blocks: from n/a through <= 2.1.9.
AplazadaMedia (6.5)0.21%—Theplus Innovation THE Plus Addons FOR Elementor PROAI7/1/202630/9/2026
Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro theplus_elementor_addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons for Elementor Pro: from n/a through < 6.3.7.
AplazadaAlta (7.1)0.14%—Tenda I24AITenda 4g03 PROAITenda 4g05AITenda 4g08AI+331/12/202517/6/2026
A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G and TEG5328F up to 65.10.15.6. Affected is an unknown function of the component Shadow File. Such manipulation with the input Fireitup leads to hard-coded credentials. An attack has to be approached locally. The exploit has been…
AplazadaAlta (7.1)0.43%—Novarad Novapacs Diagnostics ViewerAI24/12/202517/6/2026
NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.
AplazadaMedia (5.3)0.25%—T-innova DeportsiteAI13/11/202517/6/2026
Insecure Direct Object Reference (IDOR) vulnerability in DeporSite of T-INNOVA. This vulnerability allows an attacker to access or modify unauthorized resources by manipulating requests using the 'idUsuario' parameter in ‘/ajax/TInnova_v2/Formulario_Consentimiento/llamadaAjax/obtenerDatosConsentimientos’, which could…
AplazadaMedia (5.3)0.35%—GE Vernova SmallworldAI7/11/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova Smallworld on Windows, Linux allows File Manipulation.This issue affects Smallworld: 5.3.5. and previous versions.
AplazadaCrítica (9.3)0.50%—GE Vernova SmallworldAI7/11/202517/6/2026
Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue affects Smallworld: 5.3.3 and prior versions for Linux, and 5.3.4. and prior versions for Windows.
AplazadaAlta (7.5)0.30%—Karely LLC KanovaAI30/10/202517/6/2026
Kanova Android App version 1.0.27 (package name com.karelane), developed by Karely L.L.C., contains improper access control vulnerabilities. Attackers may gain unauthorized access to user details and obtain group information, including entry codes, by manipulating API request parameters. Successful exploitation could…
AplazadaMedia (6.5)0.20%—Tempranova WP Mapbox GL JSAI27/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tempranova WP Mapbox GL JS Maps wp-mapbox-gl-js allows Stored XSS.This issue affects WP Mapbox GL JS Maps: from n/a through <= 3.0.1.
AplazadaCrítica (9.3)0.55%—Novakon P SeriesAI23/9/202517/6/2026
—
AplazadaCrítica (9.4)0.22%—Novakon P SeriesAI23/9/202517/6/2026
—